VDB
GO-2025-3528
GO-2025-3528
PUBLISHED
CVSS 9.300000190734863 CRITICAL
containerd has an integer overflow in User ID handling in github.com/containerd/containerd
Risk Scores
CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | containerd/containerd | 0, 1.7.0-beta.0, 0 |
| github.com | containerd/containerd/v2 | 0, 0 |
Timeline
- Mar 18, 2025 CVE Published
- Feb 4, 2026 CVE Updated
References
- https://github.com/containerd/containerd/security/advisories/GHSA-265r-hfxg-fhmg advisory
- https://github.com/containerd/containerd/commit/05044ec0a9a75232cad458027ca83437aae3f4da patch
- https://github.com/containerd/containerd/commit/1a43cb6a1035441f9aca8f5666a9b3ef9e70ab20 patch
- https://github.com/containerd/containerd/commit/cf158e884cfe4812a6c371b59e4ea9bc4c46e51a patch